How to roll out AI across a company (2026)

A phased plan with an owner and a rough timeline for each step, the approvals to settle in week one, and the order that keeps the bill predictable. Updated September 2026.

How do you roll out AI across a company?

To roll out AI across a company, give everyone access first and then go deep one function at a time. Access takes four phases in a fixed order. Decide which teams get which models and what each team may spend, connect your identity provider so group membership becomes AI access policy, ship the assistant through the device management you already run, then watch the first two weeks and adjust per team. If identity and devices are already managed centrally, the technical work fits in an afternoon and the whole access stage in the first month. Depth is where the value is. Pick one function, put its first real workflow into production, measure quality, usage and cost, and only then move to the next function, reusing what the first team built. Rollouts that stall usually skipped the first phase and bought seats before deciding who needs which models.

The AI rollout plan, phase by phase

Six phases for a company of 100 to 1,000 people, with who owns each one, what ships at the end of it and roughly how long it takes.

Phase Owner What ships Rough timeline
1. Decide who gets what IT lead, with finance and team leads A tier map of teams to models, with a monthly budget per team Week 1
2. Connect identity IT Identity provider groups become AI access policy, with joiners and leavers handled automatically Week 1
3. Ship through device management IT The assistant on every managed laptop, already signed in Weeks 1 to 2
4. Watch the first two weeks IT, with team leads Per-team changes to model mix and budget caps Weeks 2 to 4
5. Go deep in one function Function lead, with an implementation partner The first workflow in production, with quality, usage and cost measured Months 1 to 3
6. Move to the next function The next function lead A second workflow built on the skills the first team shared Month 3 onward

Timelines assume identity and devices are already managed centrally. They are typical ranges to plan around, not a promise, and the function phases depend on how complex the first workflow is.

Access first, in this order

The first four phases give everyone access. The order matters more than the speed, and every expensive rollout we have seen went out of sequence, usually by buying before deciding.

  1. 01

    Decide who gets what

    Before you touch any tooling, map teams to model tiers.

    This is the phase people skip, and skipping it is why AI bills surprise finance three months later.

    Most companies find that a small group genuinely needs frontier models, usually engineering and a few analysts, and everyone else does excellent work on faster models that cost a fraction as much.

    Write that mapping down before you buy anything, with a monthly budget next to each team.

    It turns a vague AI project into a concrete provisioning plan, it makes the first invoice predictable, and it gives you something to adjust in phase four rather than one company-wide setting to argue about.

    Decide the mapping, not the vendor. The mapping outlives whichever model is best this quarter.

  2. 02

    Connect your identity provider

    Group membership becomes AI access policy, with no new admin.

    Connect the identity provider you already run, whether that is Okta, Microsoft Entra or Google Workspace.

    The rules you maintain anyway, departments, seniority, contractor status, become the access policy for AI, and nobody maintains a second list.

    Joiners get access on their first day because they are already in the right group, and leavers lose access the moment they are deprovisioned, at the same time they lose email.

    This is also the phase that quietly solves shadow AI, because when the sanctioned assistant is already on the laptop and already signed in, personal accounts stop being the path of least resistance.

    If you can answer "who is in the marketing group" from your identity provider today, this phase is configuration, not a project.

  3. 03

    Ship it through device management

    Distribute the assistant like every other managed app.

    Push the desktop app through the tooling you already use, Jamf or Kandji for macOS and Intune for Windows.

    Employees open their laptop and the assistant is there, already knowing who they are and which models their team is allowed.

    There are no installs to chase, no onboarding webinar required and no API keys handed out in spreadsheets.

    This is the difference between a rollout that lands in an afternoon and a pilot still limping along in month three because forty people never got round to installing anything.

    No new infrastructure. If you run an identity provider and device management, you already have everything this phase needs.

  4. 04

    Watch the first two weeks

    Adjust per team, not per company.

    The first two weeks tell you almost everything, and there are two signals to look for.

    Teams with unusually low adoption rarely need a policy change, they need one concrete use case shown by someone in their own department.

    Teams with unusually high spend rarely need a budget cut, they need a different model mix, because someone is running frontier models for work a fast model handles perfectly.

    Change those two things per team, without redeploying anything, and the rollout settles.

    Two weeks of real usage beats two months of planning meetings about hypothetical usage.

Who approves what

Most rollouts stall waiting on a sign-off nobody knew was needed.

Settle these eight in the first week and nothing waits on anyone later.

  • Budget per team. Finance approves a monthly ceiling for each team before any seat or credit is bought.
  • Model tiers. IT and each team lead agree which teams get frontier models and which default to faster, cheaper ones.
  • Data and region. Security and your data protection officer approve which data the assistant may reach and the region it is processed in, which matters under GDPR.
  • Tools and connectors. Security approves which systems and tools the assistant may call, before any are switched on.
  • Vendor terms. Legal and procurement approve the contract and the data processing agreement.
  • Acceptable use. Legal publishes a one-page policy on what employees may and may not share with AI.
  • Each workflow going live. The function lead approves go-live once the workflow passes the check you agreed at the start.
  • The goal. One executive sponsor signs off what the rollout is for and how you will know it worked.

Then go deep, one function at a time

Access should be company-wide from day one, but depth should not.

A company that tries to automate work in every department at once ends up with ten half-finished experiments and no proof that any of them paid off.

Pick one function, get one real workflow into production, measure it, and only then move on.

Pick the first function

Choose a team with a repetitive, text-heavy process, a lead who wants the change, and an output you can count.

Start where the process is best understood, not where executive interest is loudest.

Know what done looks like

The workflow runs on real work every week, a named person on the team owns it, and you know what each run costs.

Agree that check before building, so go-live is a yes or no rather than a debate.

Let the next team start ahead

The skills, connectors and approvals the first team built are shared, so the second function starts from something that already works.

How shared skills build on each other

What usually goes wrong

Six mistakes that turn a rollout into a line item nobody can defend.

Buying seats before deciding tiers

Committing to a per-seat contract for the whole company before you know who needs frontier models locks in the most expensive version of your own rollout.

Running a pilot that never ends

A twenty-person pilot proves that twenty people like AI. It does not surface the governance, spend or support questions that only appear at company scale, so the real rollout starts from zero anyway.

Treating it as a training problem

Adoption failures are usually access failures. If the assistant is not already on the laptop and already signed in, no number of enablement sessions will fix the drop-off.

One policy for everybody

Finance and engineering do not need the same models, and a single company-wide setting means you are either overpaying for most people or throttling the ones creating the most value.

Going deep everywhere at once

Ten departments each building their first workflow in the same quarter produces ten half-finished experiments and no proof that any of them paid off.

Nobody signs off the goal

Without one sponsor who says what the rollout is for, every team measures something different and the renewal conversation has no evidence in it.

Where Harriet fits

We build Harriet, so read this section as what it is.

Harriet is the golden path through the plan above, with every phase in one place.

IT provisions a desktop assistant to every managed device through the identity provider and device management it already runs.

Admins decide which models each team can use across Claude, ChatGPT, Gemini and open models, and set hard budget caps per team and per user.

Data can stay in the EU, and every prompt, model and tool call is logged.

Our team builds the first workflow with your people in phase five and hands it over.

Questions teams ask first

What is the first step in an AI rollout?

Deciding which teams get which models and what each team may spend. Do it before you buy anything. Most companies find a small group needs frontier models and everyone else does well on faster, cheaper ones, and writing that down is what makes the first invoice predictable.

How long does an AI rollout take?

If you already manage identity and devices centrally, the technical work is an afternoon. You connect your identity provider, import teams, set a default policy per team and push the app through device management. Getting access to everyone and settling the first two weeks usually takes about a month. Getting real workflows into production is measured in months, one function at a time. Companies that take months just to give people access are almost always stuck in an extended pilot rather than blocked on the deployment itself.

Should AI be rolled out to everyone or one department at a time?

Both, in different senses. Access should go to everyone at once through your identity provider and device management, because a small pilot never surfaces the spend and governance questions that decide success. Depth should go one function at a time, because building real workflows in every department at once spreads the effort too thin to prove anything.

Should we start with a pilot?

A short pilot is useful for choosing between tools. It is much less useful as a rollout strategy, because a twenty-person pilot only proves that twenty motivated people like AI. It will not show how spend behaves at scale, what audit your security team needs or what happens when someone leaves. If you can provision through identity and devices, going company-wide is usually less risky than a pilot that quietly never ends.

Who should own the AI rollout?

IT owns the mechanics, because identity and device management are already theirs, but IT should not own the model-tier decision alone. That first phase is a joint call between IT, finance and the team leads who know what their people actually do all day. One executive sponsor should own the goal. Handing the whole thing to IT as a tooling project tends to produce a clean deployment that nobody adopts, because no department ever agreed what it was for.

Who needs to approve an AI rollout?

Finance approves the budget per team, IT and the team leads agree model tiers, security and your data protection officer approve data access and the processing region, security approves tools and connectors, legal and procurement approve the vendor terms, and one executive sponsor signs off the goal. Settling all of these in the first week keeps the rollout from stalling on a sign-off nobody knew was needed.

How do we keep the AI bill under control?

Two levers do most of the work. The first is the tier mapping from phase one, which defaults everyone to capable, fast models and reserves frontier models for the teams that genuinely need them. The second is hard budget caps per team and per user, so overspend is prevented rather than discovered on an invoice. Watching the first two weeks connects the two, because that is when you find the team whose usage does not match its tier.

How do we keep company data safe during an AI rollout?

Make the sanctioned assistant the easiest option by shipping it signed in through your identity provider, decide the processing region before go-live, and log every prompt and tool call. With Harriet, data can be kept in the EU, every prompt, model and tool call is logged and exportable, and security approves which tools the assistant may call.

What does this cost with Harriet?

Harriet is priced per organization, scoped to the people it actually provisions, with no seat minimum and no annual commitment, so the rollout is not gated on a long procurement cycle. Model usage is separate and runs either through your own provider API keys, keeping any committed-spend deals you already have, or through managed credits for a single invoice with access to all the frontier labs as well as high-quality open-weight models.

Start the first phase this week.

Book 20 minutes and we'll map the plan to your identity provider, your device management and your first function.

Book a demo